diff options
| author | Albin <albin@mullvad.net> | 2025-03-04 13:13:57 +0100 |
|---|---|---|
| committer | Albin <albin@mullvad.net> | 2025-03-07 15:01:01 +0100 |
| commit | dc862f173cf2b95776a4f36759f7fa49f5c4609c (patch) | |
| tree | f1b24cd9e7d57e663a3255a23308b6a35531f7c4 | |
| parent | a14eca4428a3eb36d1ce6f5854a685a5f3cf68bd (diff) | |
| download | mullvadvpn-dc862f173cf2b95776a4f36759f7fa49f5c4609c.tar.xz mullvadvpn-dc862f173cf2b95776a4f36759f7fa49f5c4609c.zip | |
Document MASA audit
| -rw-r--r-- | audits/2025-02-24-nccgroup-android-masa.md | 16 | ||||
| -rw-r--r-- | audits/2025-02-24-nccgroup-android-masa.pdf | bin | 0 -> 61215 bytes | |||
| -rw-r--r-- | audits/README.md | 6 |
3 files changed, 22 insertions, 0 deletions
diff --git a/audits/2025-02-24-nccgroup-android-masa.md b/audits/2025-02-24-nccgroup-android-masa.md new file mode 100644 index 0000000000..f6ac0c2e1a --- /dev/null +++ b/audits/2025-02-24-nccgroup-android-masa.md @@ -0,0 +1,16 @@ +# 2025-02-24 - NCC Group MASA of our Android app + +A team from NCC Group conducted a Mobile Application Security Assessment (MASA) +of our Android app. + +# Result + +The Android app passed all controls. + +## MASA certificate + +The MASA certificate is hosted by App Defence Alliance: +* [2025-02-24 MASA certificate](https://appdefensealliance.dev/reports/net.mullvad.mullvadvpn_1740398400000000.pdf) + +We also host certificate in our repository: +* [2025-02-24 MASA certificate](2025-02-24-nccgroup-android-masa.pdf) diff --git a/audits/2025-02-24-nccgroup-android-masa.pdf b/audits/2025-02-24-nccgroup-android-masa.pdf Binary files differnew file mode 100644 index 0000000000..aa429d01a8 --- /dev/null +++ b/audits/2025-02-24-nccgroup-android-masa.pdf diff --git a/audits/README.md b/audits/README.md index 5d0773a471..fe7712c0f1 100644 --- a/audits/README.md +++ b/audits/README.md @@ -11,3 +11,9 @@ performed on this app so far: * [2020-06-12 - Cure53](./2020-06-12-cure53.md) * [2022-10-14 - Atredis](./2022-10-14-atredis.md) * [2024-12-10 - X41 D-Sec](./2024-12-10-X41-D-Sec.md) + +## Additional audits and certifications + +Apart from the biannual audits mentioned above, we've also conducted the the following: + +* [2025-02-24 - NCC Group Mobile Application Security Assessment (MASA) of the Android app](./2025-02-24-nccgroup-android-masa.md) |
